You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

寻找Azure PowerShell/Azure CLI中的强身份验证及等效命令

强身份验证相关查询与Get-MsolUserByStrongAuthentication的替代方案

Hey there, let's break this down clearly. The Get-MsolUserByStrongAuthentication cmdlet belongs to the legacy MSOnline (Azure AD PowerShell) module, which Microsoft has deprecated in favor of the Microsoft Graph PowerShell module. Below are the equivalent ways to get the same (and more granular) info using both Microsoft Graph PowerShell and Azure CLI, plus extra context on strong authentication queries.

Azure PowerShell (Microsoft Graph)

First, make sure you have the required module installed and connected:

# Install the module (if not already installed)
Install-Module Microsoft.Graph.Users.Authentication -Force -AllowClobber

# Connect to Microsoft Graph with the necessary scope
Connect-MgGraph -Scopes UserAuthenticationMethod.Read.All

Direct replacement for Get-MsolUserByStrongAuthentication

The legacy cmdlet returned users with strong authentication enabled. In Microsoft Graph, we check for non-password authentication methods (since these are the "strong" methods like MFA, Authenticator app, phone calls, FIDO2 keys, etc.).

To get all strong authentication methods for a single user:

Get-MgUserAuthenticationMethod -UserId john.doe@contoso.com | 
    Where-Object { $_.AdditionalProperties["@odata.type"] -notin "#microsoft.graph.passwordAuthenticationMethod" }

To bulk list all users who have at least one strong authentication method configured:

Get-MgUser -All $true | ForEach-Object {
    $strongAuthMethods = Get-MgUserAuthenticationMethod -UserId $_.Id | 
        Where-Object { $_.AdditionalProperties["@odata.type"] -notin "#microsoft.graph.passwordAuthenticationMethod" }
    
    if ($strongAuthMethods) {
        [PSCustomObject]@{
            UserPrincipalName = $_.UserPrincipalName
            StrongAuthMethods = $strongAuthMethods.AdditionalProperties["@odata.type"] -replace "#microsoft.graph.", ""
            MethodCount       = $strongAuthMethods.Count
        }
    }
}

Bonus: Check user-level MFA enforcement (legacy vs modern)

Note that modern Azure AD uses Conditional Access policies to enforce MFA, rather than the old user-level "StrongAuthenticationRequirements" property. If you still need to check legacy user-level settings, you can use:

Get-MgUser -UserId john.doe@contoso.com -Property StrongAuthenticationRequirements | 
    Select-Object UserPrincipalName, StrongAuthenticationRequirements

Azure CLI

For Azure CLI, the workflow is similar—we target user authentication methods and filter out password-based ones.

First, log in to Azure CLI:

az login

Get strong authentication methods for a single user

az ad user authentication-method list --user john.doe@contoso.com \
    --query "[?@odata.type != '#microsoft.graph.passwordAuthenticationMethod']" \
    --output table

Bulk list users with strong authentication enabled

Using jq for parsing (install jq if you don't have it):

# Get all user UPNs
az ad user list --query "[].userPrincipalName" -o tsv | while read upn; do
    # Count non-password authentication methods
    method_count=$(az ad user authentication-method list --user "$upn" \
        --query "[?@odata.type != '#microsoft.graph.passwordAuthenticationMethod'] | length" -o tsv)
    
    if [ "$method_count" -gt 0 ]; then
        echo "$upn has $method_count strong authentication method(s)"
    fi
done

内容的提问来源于stack exchange,提问作者Jess

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.12 04:23:51